| File name: | bitcoin-0.1.0.rar |
| Full analysis: | https://app.any.run/tasks/406b2a06-f351-4f3b-8965-918c56382173 |
| Verdict: | Malicious activity |
| Analysis date: | April 23, 2024, 14:26:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-rar |
| File info: | RAR archive data, v4, os: Win32, flags: Solid |
| MD5: | 91E2DFA2AF043EABBB38964CBF368500 |
| SHA1: | EC9ED4CCBC990ECEB922FF0C4D71D1AD466990DD |
| SHA256: | 8B17EB9A5707F2519DEFDA4CDF8D14FA1B8DEE630E11E6EF85FF9F5547555B56 |
| SSDEEP: | 98304:nti8wbXqzG7tKYMy40WqhtR6nIzU39UxlkjeN0WPeJURX7/uFnzNoWucjPmSCUsD:q3xuhRw |
| .rar | | | RAR compressed archive (v-4.x) (58.3) |
|---|---|---|
| .rar | | | RAR compressed archive (gen) (41.6) |
| CompressedSize: | 1000 |
|---|---|
| UncompressedSize: | 2693 |
| OperatingSystem: | Win32 |
| ModifyDate: | 2009:01:07 01:00:00 |
| PackingMethod: | Best Compression |
| ArchivedFileName: | src\makefile |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | "C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\bitcoin-0.1.0.rar | C:\Program Files\WinRAR\WinRAR.exe | explorer.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.91.0 Modules
| |||||||||||||||
| 548 | "C:\Windows\system32\taskmgr.exe" /4 | C:\Windows\System32\taskmgr.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Task Manager Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 796 | "C:\Users\admin\Desktop\bitcoin.exe" | C:\Users\admin\Desktop\bitcoin.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 3248 | "C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\bitcoin.exe" | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\bitcoin.exe | WinRAR.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3489660927 Modules
| |||||||||||||||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtBMP |
Value: | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\Interface\Themes |
| Operation: | write | Name: | ShellExtIcon |
Value: | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 3 |
Value: C:\Users\admin\Desktop\phacker.zip | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 2 |
Value: C:\Users\admin\Desktop\Win7-KB3191566-x86.zip | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 1 |
Value: C:\Users\admin\Desktop\curl-8.5.0_1-win32-mingw.zip | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\ArcHistory |
| Operation: | write | Name: | 0 |
Value: C:\Users\admin\AppData\Local\Temp\bitcoin-0.1.0.rar | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | name |
Value: 120 | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | size |
Value: 80 | |||
| (PID) Process: | (324) WinRAR.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\FileList\FileColumnWidths |
| Operation: | write | Name: | type |
Value: 120 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\addressbook16.bmp | image | |
MD5:442307926BC3FCC2118E67D7EB9D0F1D | SHA256:A8687DC93616BA8D56A44C4EDD52E1B6DC93B87B97B8177A65B369B3E9C4F853 | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\makefile | text | |
MD5:6915D8E33CD93261EB9D1272E3799EC0 | SHA256:FA2F6C3031EB8625E24AA012FA7C0D6E17C7F61E7B9604D45CDE5B7BFDADE161 | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\addressbook16mask.bmp | binary | |
MD5:D2D7A8E2781E93BEBE3509DE3DAF83B1 | SHA256:A22071608F7E38B4B18F69D87123F6D7429710E8EA7B5370F1C86B14193FBF50 | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\addressbook20.bmp | image | |
MD5:5A0474014AB8CEB34007A8615BD36A08 | SHA256:76FE6679DA5C4D9FD763084A19D1D0CF0EB3FB78F8799BA064E912D1AB4B0B10 | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\send20mask.bmp | image | |
MD5:D96799FAD965ABB565A31E77CF6A203E | SHA256:EFB5D66BB902A281406D3B5CC4092008DBDCB5C77B298C06B3EF79E8BFA16160 | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\main.cpp | text | |
MD5:E04B403D08684267AD12CA71D244BFD4 | SHA256:C89F44185DF7FF5D68342E5F533AE1282D5CF1259306D14C1C79315E973E0E1C | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\send16masknoshadow.bmp | image | |
MD5:96884C7DA51CB665BD5EACD570E412C7 | SHA256:08C7EFFF95FC90A198DD190E50761281CBFAB42E17F064B7146D952D94601749 | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\addressbook20mask.bmp | image | |
MD5:9695939B90508BBD4C9F815E5CF3623D | SHA256:392154912BD31605DEE19DF89E999DB180BFA5A595A668EF097D5D3338FBEDC8 | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\db.cpp | text | |
MD5:971D002AA007AB2C577FA3DB5D234767 | SHA256:2B83D2432AA19BA3FACECA58C0B610A715747089EC2D6ED580CD915B53C1A5AC | |||
| 324 | WinRAR.exe | C:\Users\admin\AppData\Local\Temp\Rar$EXa324.22218\src\rc\send20.bmp | image | |
MD5:A3D4481F61C796DEACFDF55BCF9B1C6B | SHA256:B4959CA84A316E494E2D5B61F406E54344249ACE24B854E90F34D5DEACCF61C3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3248 | bitcoin.exe | 72.233.89.199:80 | — | RMH-14 | US | unknown |
796 | bitcoin.exe | 72.233.89.199:80 | — | RMH-14 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
dns.msftncsi.com |
| shared |
Process | Message |
|---|---|
bitcoin.exe | sending: version (46 bytes)
|
bitcoin.exe | RandAddSeed() got 154720 bytes of performance data
|
bitcoin.exe | |
bitcoin.exe | |
bitcoin.exe | Bitcoin CMyApp::OnInit()
|
bitcoin.exe | |
bitcoin.exe | |
bitcoin.exe | |
bitcoin.exe | |
bitcoin.exe | |